The full anatomy of a phishing site,
one URL at a time.
ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.
No phishing signals detected
| URL | hxxps://youtube[.]com/shorts/e1QmUns3JV8?si=jRiv7QLUyW68Vjq4 | |
| Host | youtube[.]com | |
| Brand | YouTube | |
| Screenshot | https://cdn.zerophish.ai/f440a6e3-9168-4650-8cb6-07d55ed28eb2.jpg | |
| Scan ID | 26c4564a-677b-48ad-8368-49eadc3a6cdc |
|
395 d ago
|
REVIEW | www.youtube.com | safe |
| Host | youtube.com |
| Registered domain | youtube.com |
| Scheme | https |
| Content length | 1649769 B |
| HTTP | 200 · text/html |
| JARM | 0d39b39b30d30d37d20320327d20122de7c02fe862e334985aa656e5df0651 |
| Redirect hops | 4 |
Assessment (YouTube Shorts page)
What the page appears to be
This page is presenting a standard YouTube Shorts experience (video header, navigation like Home / Shorts / Subscriptions, and account entry). The OCR text includes typical YouTube UI such as “Skip navigation”, “Sign in to like videos, comment, and subscribe.”, and footer items like “TermsPrivacyPolicy & Safety” and “© 2026 Google LLC.”
Suspicious elements found (phishing signals)
None of the commonly used phishing patterns are present in the provided HTML/OCR:
- No credential-harvesting form visible in the supplied content. The page shows sign-in links pointing to Google’s accounts system, not a custom login form.
- No fake security warnings / urgency cues (e.g., “your account will be closed”) were observed.
- No mismatched branding: the content and navigation clearly align with YouTube.
- No suspicious redirects/domains are evident in the snippet. The sign-in destination uses accounts.google.com with a continue parameter back to a youtube.com/shorts URL.
Concrete relevant details from the HTML:
-
The login link is:
https://accounts.google.com/ServiceLogin?service=youtube...&continue=https%3A%2F%2Fwww.youtube.com%2Fsignin...&next=https%253A%252F%252Fwww.youtube.com%252Fshorts%252Fe1QmUns3JV8%253F... - The page title shown in HTML is: “… - YouTube”, and the OCR footer matches Google/YouTube standard text.
Brand and URL relationship
- Identified brand: YouTube
-
URL domain:
youtube.com(matches YouTube’s real domain) - The sign-in flow goes through accounts.google.com, which is expected for YouTube authentication.
Verdict
Legitimate: The page content and linked authentication endpoints match official YouTube/Google behavior, and there are no observed phishing-specific UI elements (no credential form impersonation, no fake warnings, no suspicious brand mismatch).